CrowdSec Agent
Local detection, global remediation

CrowdSec agent defends against intrusions by analyzing logs and identifying and blocking offending IPs. Flagged IPs are then sent to the community blocklist to protect the Crowd.
Get started for freeGet started for free
01/04

Real-time detection of suspicious traffic & behavior

CrowdSec Agent, an intrusion prevention system, protects against attacks on any server by parsing real-time service logs (servers, SSH, Wordpress etc. logs). The agent detects behaviors that indicates an intrusion or unauthorized action.


  • A variety of scenarios to detect attacks: bruteforce, HTTP attacks, scans, L7 DDOS, website scalping/scrapping etc.
  • Compatible with most OS (Linux/BSD/Windows) and  all popular servers (Nginx, Apache, Traefik, Caddy etc.). Also working in a container-type of setup and can be used at the application level with WordPress, Magento, or any PHP or Python-based website.
  • Written in Go to ensure fast execution and low memory footprint. It comes with an easy-to-install setup wizard and integrates seamlessly with any CI/CD or cybersecurity process.
02/04

Our bouncer blocks cyberattacks

CrowdSec Agent comes with a remediation component, called "bouncer", to act upon identified threats. It will interface with existing software such as firewalls to ban or block nefarious IPs. The bouncer will also consume the community blocklist to preventively block IPs that have been shared by the community of CrowdSec users.

  • Compatible with most firewalls, whether they come with Linux (iptables, nftables) or dedicated OS such as OPNSense. The bouncer supports also web application firewalls such as Cloudflare or AWS WAF.
  • Decoupled from the detection mechanism for flexible setups where detection is done on one machine, while remediation is achieved on other machines.
  • Customizable. While bouncers are usually used to ban/block IPs or insert Captcha challenges, custom bouncers can be created to execute any script.
03/04

Community-fueled blocklist

CrowdSec uses the intelligence of the crowd to maintain and distribute IP blocklists to preventively block intrusions.

  • CrowdSec implements a curation mechanism to ensure the quality and reliability of the data sent back to users. Combining user reputation, correlations with third-party services and data from our own honeypot network, the consensus engine ensures blocklists contain only "shoot-on-sight" IP addresses.
  • IP dangerousity is highly dynamic in time. As CrowdSec receives constant data from its users, we are able to monitor and deliver fast updates ensuring IPs reputation is always up.
  • The curation engine ensures that blocklists contain no false positives or poisoning attempts, allowing to focus on really dangerous IPs.
04/04

Open source since day 1

CrowdSec has been created by developers with strong background in FOSS. For us, open-sourcing CrowdSec Agent is paramount to guarantee full transparency, quality and reliability to our users, while offering the community the opportunity to contribute at the code base.

  • Open-sourced under the MIT license, the most permissive in the world.
  • We welcome contributions from the community whether it is to enhance the code base of Agent or to create new attack detection scenarios, bouncers or ports on new platforms.
  • The CrowdSec Hub centralizes all detection scenarios, bouncers or collections developed by the CrowdSec team and the community. Check it out for the latest updates!

How the Crowdsec Agent works

The feed can be consumed by your firewall or any existing remediation mechanism.

Why use our Agent

Reduce intrusions by 90%

By using CrowdSec Agent, users noticed a 90% drop in intrusion attempts on their online services, due to the community blocklist containing the curated list of most aggressive IPs.

Eliminate alert fatigue with 0 false positive

By preventively blocking aggressive IPs, and Internet background noise, SOC teams and security analysts can focus on alerts that matter.

Seamless setup

CrowdSec Agent was developed to fit the needs of modern IT setups. Working with all popular server OS, containers, servers and applications, Agent is easy to setup and integrates effortlessly your CI/CD process.

CrowdSec Agent in few figures

CrowdSec has quickly grown to become the biggest crowd-powered CTI network.

3M

Rogue IPs in the CTI database

30K

"Shoot-in-sight" IPs in the blocklist

1.5M

Signals/day received from the community

+50K

Machines contributing to the CTI

Why use our Agent

Reduce intrusions by 90%

By using CrowdSec Agent, users noticed a 90% drop in intrusion attempts on their online services, due to the community blocklist containing the curated list of most aggressive IPs.

Eliminate alert fatigue with 0 false positive

By preventively blocking aggressive IPs, and Internet background noise, SOC teams and security analysts can focus on alerts that matter.

Seamless setup

CrowdSec Agent was developed to fit the needs of modern IT setups. Working with all popular server OS, containers, servers and applications, Agent is easy to setup and integrates effortlessly your CI/CD process.

Run the Agent effectively on multiple platforms

OS

Linux
Linux
Coming soon
BSD
BSD
Coming soon
Apple
Apple
Coming soon
Windows
Windows
Coming soon
Open WRT
Open WRT
Coming soon

Services

Iptables
Iptables
Coming soon
Nftables
Nftables
Coming soon
Nginx
Nginx
Coming soon
Apache
Apache
Coming soon
Caddy
Caddy
Coming soon
PF
PF
Coming soon

Data sources

AWS Cloudwatch
AWS Cloudwatch
Coming soon
Amazon Kinesis
Amazon Kinesis
Coming soon
Docker
Docker
Coming soon

Platforms

Cloudflare
Cloudflare
Coming soon
GCP
GCP
Coming soon
AWS
AWS
Coming soon
Docker
Docker
Coming soon
Traefik
Traefik
Coming soon
Envoy
Envoy
Coming soon

Discover how companies are using our CTI

Select
esyoil is using CrowdSec Agent to bring multiple data sources together and block IPs even before they do something bad, leveraging log analysis.
John DOE
 - 
CEO at Acme Inc.
EsyOil
Yannick Siegler has been one of our earliest adopters and most involved community member. Discover his CrowdSec Agents use cases, both for personal and professional use.
John Doe
 - 
CEO at Acme Inc.
Siegler Informatique
We had a chat with Dyllan Pascoe, co-founder of Lookopen. Find out how he used CrowdSec Agent and how it helped him secure his clients' IT assets.
John DOE
 - 
CEO at Acme Inc.
Lookopen

Get started with CrowdSec today

Install an agent
Select

$ curl -s https://packagecloud.io/install/repositories/crowdsec/crowdsec/script.deb.sh | sudo bash
$ sudo apt-get install crowdsec

COPY CODE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

$ curl -s https://packagecloud.io/install/repositories/crowdsec/crowdsec/script.rpm.sh | sudo bash
$ sudo yum install crowdsec

COPY CODE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

$ sudo apt-get install crowdsec

COPY CODE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

$ docker run -d -v acquis.yaml:/etc/crowdsec/acquis.yaml -e COLLECTIONS="crowdsecurity/sshd" -v /var/log/auth.log:/var/log/auth.log -v /path/mycustom.log:/var/log/mycustom.log --name crowdsec crowdsecurity/crowdsec

COPY CODE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

# pkg install crowdsec

COPY CODE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

$ wget -qO - https://github.com/crowdsecurity/crowdsec/releases/latest/download/crowdsec-release.tgz | tar zxvf -
$ cd crowdsec-v* && sudo ./wizard.sh -i

COPY CODE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

DIVE INTO CROWDEC’S UNIVERSE

Get started with
the Console today